Privacy Policy

Effective March 2, 2026

CardFinch ("we," "us," or "our") operates the CardFinch website and service. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using CardFinch you agree to the practices described here and to our Terms of Service.

Information We Collect

Account information
When you sign up we collect your name and email address. If you sign in with Google, we receive your name, email, and profile picture from Google.
Contacts and addresses
You may store recipient names, mailing addresses, birthdays, and custom events in your address book. If you import contacts from Google or a file, we store only the data you choose to import.
Orders and card designs
We store your order history, card designs, messages, and any images you upload or generate using our AI tools.
Payment information
Payments are processed entirely by Stripe. We never see or store your credit card number. We receive only a transaction reference and payment status from Stripe.
Usage and session data
We collect standard server logs (IP address, browser type, referring page) and use session cookies to keep you signed in.

How We Use Your Information

  • To create and manage your account
  • To process, print, and mail your card orders
  • To send order confirmations, status updates, and occasion reminders you've opted into
  • To provide customer support
  • To detect and prevent fraud or abuse
  • To improve the service and fix bugs

Third-Party Services

We share data only with the services needed to operate CardFinch. We never sell your personal information.

Stripe
Processes payments. Receives your email and transaction details. See Stripe's Privacy Policy.
Google
Provides sign-in (OAuth) and optional contact import. We request only the permissions needed and do not access your Google data beyond what you authorize.
Customer's Canvas
Powers our card editor and generates print-ready files. Receives your card design data.
Tango Card
Fulfills digital gift cards included with greeting cards. Receives gift card order details.
Amazon Web Services (AWS)
Hosts the application, database, and uploaded images. All data is stored in the United States.
OpenAI
Powers AI image generation in the card editor. Receives only the text prompts you submit — no personal data is sent.

Cookies & Sessions

We use a session cookie to keep you signed in. We do not use third-party advertising or tracking cookies. No data is sold to advertisers.

Data Retention

We retain your account data, contacts, designs, and order history for as long as your account is active. If you request account deletion, we permanently delete all associated data within 30 days. Server logs are retained for up to 90 days.

Your Rights

  • Access — You can view and export your data at any time from your account.
  • Correction — You can update your information in Settings or by contacting support.
  • Deletion Contact support to request permanent deletion of your account and data.
  • Opt out — You can disable email notifications in Settings.

Children's Privacy

CardFinch is not intended for children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the site. Your continued use of CardFinch after changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us.

See also our Terms of Service.